2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21255MEDIUM5.7GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2021-27885HIGH8.8usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
CVE-2021-22296MEDIUM5.5A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file sys...
CVE-2021-22294LOW3.3A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may exploit this vulnerabili...
CVE-2021-22187MEDIUM4.3An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaus...
CVE-2021-3384MEDIUM5.3A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP table...
CVE-2021-25330HIGH7.5Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions i...
CVE-2021-21514MEDIUM4.9Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote ...
CVE-2021-21513CRITICAL9.8Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server ...
CVE-2021-27904MEDIUM5.5An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, th...
CVE-2021-27901MEDIUM6.8An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because...
CVE-2021-21322CRITICAL9.8fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with h...
CVE-2021-21321CRITICAL10fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In...
CVE-2021-21320MEDIUM4.3matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0...
CVE-2021-27730CRITICAL9.8Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. Th...
CVE-2021-27888MEDIUM6.1ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.
CVE-2021-27804CRITICAL9.8JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.
CVE-2021-27731MEDIUM6.1Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed ve...
CVE-2021-25309CRITICAL9.8The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout...
CVE-2021-25306HIGH7.5A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers...
CVE-2021-27886CRITICAL9.8rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metachara...
CVE-2021-27884MEDIUM5.1Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tok...
CVE-2021-3342CRITICAL9.8EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a...
CVE-2021-27878HIGH8.8An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc...
CVE-2021-27877CRITICAL9.8An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authenticat...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now